Reply
Old February 18th, 2005 Top | #21

OSNN Folding Team  
NetRyder's Avatar
Tech Junkie
Joined: April 2002
Location: New York City
Posts: 13,256
Reputation: 4260
Power: 294

Default Re: Mozilla/Firefox security exploit: Disable IDN support

Yet another temporary fix:
Darin Fisher, network supremo, has pulled it out of the bag and come up with a less drastic short-term solution to the IDN problem. It has just been checked in for all three upcoming releases. Read about it over in bug 282270, but basically IDN will still work, but all occurrences of IDN domains in the browser UI (URL bar, security info etc.) will be the punycode form. There is a pref to re-enable full IDN - set "network.IDN_show_punycode" to false. As with the previous plan, this preference will be set to true in all official builds.

As I've said in previous blogposts, turning off IDN entirely was always an suboptimal solution, and I'm very pleased we've managed to find a third way. The search goes on for something better long-term - I'm sure you'll all agree that, while showing the punycode domain all the time solves the immediate spoofing problem, the fewer browsers out there that do it, the better.
http://weblogs.mozillazine.org/gerv/...es/007586.html
NetRyder is offline   Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
building Mozilla and Firefox Complete Web Design & Coding 7 August 27th, 2005 3:37am
Mozilla Firefox 1.0.5 released NetRyder Windows Desktop Systems 7 July 13th, 2005 6:14am
mozilla (firefox) ? mooo Green Room 12 April 5th, 2005 10:57pm
Mozilla Firefox Icon (PNG) NetRyder Desktop Customisation 20 February 10th, 2004 10:33am
Tip: Disable New Windows (Mozilla) SPeedY_B Windows Desktop Systems 6 February 9th, 2003 10:47pm